296,349
Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a Newsletter category field.
Software | From | Fixed in |
---|---|---|
link3 / simplenews | - | 5.x-1.4.x |
link3 / simplenews | - | 6.x-1.0.x |
link3 / simplenews | 4.6.x-1.x-dev | 4.6.x-1.x-dev.x |
link3 / simplenews | 4.7.x-1.0 | 4.7.x-1.0.x |
link3 / simplenews | 4.7.x-1.x-dev | 4.7.x-1.x-dev.x |
link3 / simplenews | 4.7.x-2.x-dev | 4.7.x-2.x-dev.x |
link3 / simplenews | 5.x-1.0 | 5.x-1.0.x |
link3 / simplenews | 5.x-1.1 | 5.x-1.1.x |
link3 / simplenews | 5.x-1.2 | 5.x-1.2.x |
link3 / simplenews | 5.x-1.3 | 5.x-1.3.x |
link3 / simplenews | 5.x-1.x-dev | 5.x-1.x-dev.x |
link3 / simplenews | 6.x-1.0-beta1 | 6.x-1.0-beta1.x |
link3 / simplenews | 6.x-1.0-beta2 | 6.x-1.0-beta2.x |
link3 / simplenews | 6.x-1.x-dev | 6.x-1.x-dev.x |